Makes rules easier to manage via our module
Our module should be easier to manage than using directly the auditd rules:
eg:
-
audit_user_list
could be a list parameter with all the users we want to know all actions -
audit_path_list
could be a parameter with all the path monitored where we know everything that happens